Privacy Policy

Effective Jul 28, 2026

Nobel Life Systems LLC, a New York limited liability company, operates ismysitehackable.com and is responsible for the personal data described in this policy. Is My Site Hackable? is built to collect as little as possible. This policy explains what we collect, why, who we share it with, and the choices you have.

What we collect

  • The URL you submit and the results of scanning it (findings, severities, and the generated report).
  • Your email: optional for a free scan; required for an account.
  • Your acceptance of our terms: when you accept them on a scan, we store the terms version, a timestamp, and the IP address you accepted from.
  • Account identifiers for signed-in users (managed by Amazon Cognito).
  • Billing metadata from our payment processor (such as your customer and subscription identifiers). We never receive or store your raw card details.
  • Branding assets, on an Agency plan: the brand name, accent color, and logo you upload. Your logo is stored in public-read storage because it is displayed on the client-facing reports and badges you generate; don't upload anything you wouldn't want served publicly.
  • Client-authorization attestations, on an Agency plan: when you attest that you're authorized to actively test a client's domain, we record the clause version you accepted, who attested, a timestamp, and the IP address.
  • Minimal operational logs needed to run and secure the Service.

What we deliberately don't store

If a scan discovers a secret (an API key, token, or similar), we never store or log it in readable form, it is redacted or hashed before anything is written down. We never store raw payment-card data; card details are handled entirely by our payment processor.

How we use it

  • to run your scans and deliver your reports;
  • if you give us your email, to send your report and occasional follow-up security guidance (you can unsubscribe at any time);
  • to operate accounts, subscriptions, and billing;
  • to keep the Service secure and prevent abuse;
  • to maintain and improve how the Service works.

Who we share it with

We don't sell your data. We share it only with the service providers we need to run the product:

  • Amazon Web Services: hosting, storage, and infrastructure.
  • Amazon Cognito: account sign-in.
  • Anthropic: we send scan findings (with secrets already redacted) to generate the plain-language fix guidance in your report. For paid active scans, our AI agent may also send portions of the pages and responses it retrieves from your verified site so it can analyze them; we strip recognizable secrets before sending, but that content is not otherwise filtered.
  • Kit (ConvertKit): if you give us your email to receive a report, we share your email and basic scan context (the site you scanned, the top finding, and a link to your report) so we can send you the report and follow-up guidance.
  • Google (Ads conversion tracking): if you arrive from a Google Ads campaign, we report back that a conversion happened (for example, a scan completed or a signup finished) so the campaign can be measured. We never send Google your email or the site you scanned, only that the conversion occurred.
  • Microsoft (Clarity): on our marketing pages, Clarity records session replay, mouse movement, clicks, and scroll depth so we can see how the site is used. It does not run on your scan report, dashboard, verification, or welcome pages.

We may also disclose information if required by law, or to protect the rights, safety, and security of the Service and its users.

Retention

We keep data only as long as needed. Free-scan results are short-lived and expire automatically. If you give us your email to receive a report, we keep it (and the list of sites you scanned) until you ask us to delete it. Account and billing records are kept while your account is active and for as long as we're required to retain them afterward. We also keep anonymous, aggregate counters (such as how many sites we've scanned) indefinitely; these hold no personal data.

Cookies

To keep you signed in, we store your session token in your browser's local storage rather than in a cookie. If you arrive from a Google Ads campaign, Google's tracking script sets its own advertising cookies and reads the ad-click identifier attached to the link you clicked, so we (and Google) can tell which ad led to a scan or signup. That script loads only on pages a Google Ads visitor can land on or convert through, not across the whole Service. On our marketing pages, Microsoft Clarity sets its own cookies (_clck and _clsk) to recognize repeat visits and stitch together a browsing session. When we test two versions of a page against each other, we set our own cookies to keep the version you see consistent and to measure which one performs better. These are named ab_<test>, ab_props, and ab_x_<test>; they hold a random visitor id plus which version of the page you were shown, last 30 days, and are first-party cookies that never leave this site.

Analytics

We use Plausible Analytics to understand aggregate traffic and how the scan funnel performs. It is cookieless and collects no personal data (no cross-site tracking and no advertising profiles), so no consent banner is needed. We never send it your email or the URL you scanned. The only scan-derived value it receives is a coarse severity category (for example, “critical” or “clean”) with no link back to your site, so its events stay anonymous and aggregate.

Your choices and rights

You can request access to, correction of, or deletion of the personal data we hold about you by emailing us. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we'll honor those rights as required.

Security and data location

Data is encrypted in transit, access is least-privilege, and active scans egress from a dedicated address for traceability. The Service runs on AWS infrastructure in the United States; if you use it from elsewhere, your data is processed there.

Children

The Service isn't directed to children, and we don't knowingly collect data from anyone under 16.

Changes

We may update this policy; the effective date above will change when we do. Significant changes will be made clear on this page.

Contact

Privacy questions or requests? Email security@ismysitehackable.com. See also our Terms of Service.